Australian Data Breach Notification Scheme: Complete Compliance Guide
Since February 2018, Australian organisations have operated under one of the world's most consequential privacy accountability frameworks: the Notifiable Data Breaches (NDB) scheme. Introduced through amendments to the Privacy Act 1988, the scheme fundamentally changed how businesses must respond when personal information is compromised. With penalties now reaching up to AU$50 million per contravention following the 2022 reforms, understanding your obligations is no longer optional — it's a core business risk issue.
This guide walks Australian organisations through everything they need to know about the Notifiable Data Breaches scheme: who it applies to, what counts as an eligible breach, how quickly you must respond, and what practical steps you can take to stay compliant.
What Is the Australian Data Breach Notification Scheme?
The Notifiable Data Breaches (NDB) scheme is an Australian federal regulatory framework that requires entities covered by the Privacy Act 1988 to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when an "eligible data breach" occurs. It came into force on 22 February 2018 under Part IIIC of the Privacy Act.
The scheme's underlying purpose is straightforward: give individuals the information they need to protect themselves when their personal data has been exposed, and create accountability for organisations that handle Australian personal information.
Who the Scheme Applies To
The NDB scheme applies to all entities that already have obligations under the Australian Privacy Principles (APPs). This includes:
- Australian Government agencies
- Businesses and not-for-profits with an annual turnover of more than AU$3 million
- Private sector health service providers (regardless of turnover)
- Credit reporting bodies and credit providers
- Tax File Number (TFN) recipients
- Entities that trade in personal information
- Some small businesses that opt in or are otherwise captured (e.g., contracted service providers to the Commonwealth)
Recent legislative reform proposals aim to remove the small business exemption entirely, meaning even smaller operators should be preparing for compliance obligations.
What Counts as an "Eligible Data Breach"?
An eligible data breach under the NDB scheme is a data breach that meets three specific criteria under section 26WE of the Privacy Act:
- There is unauthorised access to, unauthorised disclosure of, or loss of personal information held by the entity.
- The breach is likely to result in serious harm to one or more individuals whose personal information was affected.
- The entity has not been able to prevent the likely risk of serious harm through remedial action.
What "Serious Harm" Means
Serious harm is not defined narrowly in the Act, but the OAIC interprets it broadly. It can include:
- Financial or economic harm (fraud, identity theft, unauthorised transactions)
- Physical harm or threats to safety (e.g., disclosure of a domestic violence victim's address)
- Psychological or emotional harm
- Reputational damage
- Loss of employment or business opportunities
- Discrimination or harassment
When assessing whether serious harm is "likely," organisations must consider factors such as the type and sensitivity of information involved, whether it was protected by security measures like encryption, the persons or types of persons who have obtained (or could obtain) the information, and the nature of the harm itself.
The 30-Day Assessment Rule
If an organisation suspects an eligible data breach may have occurred but isn't certain, the Privacy Act requires them to carry out a reasonable and expeditious assessment within 30 calendar days of becoming aware of the grounds for suspicion.
This three-stage assessment typically follows this structure:
- Initiate: Decide who is responsible for conducting the assessment and set a timeline.
- Investigate: Gather relevant facts about the incident — what information was involved, how, when, and who might be affected.
- Evaluate: Make an evidence-based decision about whether the incident meets the threshold of an eligible data breach.
If, at any point during the assessment, it becomes clear the breach is eligible, the notification obligation is triggered immediately — you don't get to use the remainder of the 30 days.
Notification Requirements: What, Who, and How
Once an organisation determines an eligible data breach has occurred, they must, as soon as practicable, prepare a statement and notify both the Commissioner and affected individuals.
What the Statement Must Contain
The notification statement, which must be lodged with the OAIC using its online Notifiable Data Breach form, must include:
- The identity and contact details of the entity
- A description of the eligible data breach
- The kinds of information involved
- Recommendations about steps individuals should take to respond
Options for Notifying Individuals
The Privacy Act sets out three options for notifying affected people:
| Option | When to Use | Method |
|---|---|---|
| Option 1: Notify all individuals | When you can identify everyone whose data was involved | Direct notification (email, phone, letter) |
| Option 2: Notify only at-risk individuals | When you can identify only those at risk of serious harm | Direct notification to that subset |
| Option 3: Publish a statement | When neither of the above is practicable | Publish on your website and take reasonable steps to publicise it |
Penalties for Non-Compliance
The consequences for failing to comply with the NDB scheme were dramatically strengthened by the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022. For serious or repeated interferences with privacy, penalties for body corporates can now reach the greater of:
- AU$50 million; or
- Three times the value of any benefit obtained through the misuse of information; or
- 30% of the entity's adjusted turnover during the relevant period
Beyond financial penalties, the OAIC has enhanced powers to conduct assessments, issue infringement notices, and publish enforcement outcomes. Reputational damage from a poorly handled breach — like those seen with Optus, Medibank, and Latitude Financial — can far exceed the direct financial penalty.
How to Prepare: A Practical Compliance Checklist
Preparation is the single biggest factor determining whether a data breach becomes a manageable incident or a business-defining crisis. Here's a practical checklist for Australian organisations:
1. Know Your Data
You can't protect what you don't understand. Conduct a data mapping exercise to document:
- What personal information you collect
- Where it's stored (systems, geographies, third parties)
- Who has access to it
- How long you retain it
2. Build a Data Breach Response Plan
The OAIC strongly recommends every entity have a documented response plan. It should include:
- Roles and responsibilities (incident lead, legal, comms, IT)
- Escalation procedures
- Assessment methodology aligned with the 30-day rule
- Template notification statements
- Communication protocols for the OAIC, affected individuals, and the public
3. Implement Reasonable Security Controls
APP 11 requires you to take "reasonable steps" to protect personal information. In practice this means multi-factor authentication, strong encryption at rest and in transit, patch management, access controls based on least-privilege, staff training, and vendor risk management.
For public-facing links and communications — such as marketing emails, campaign URLs, or customer-facing short links — using platforms with built-in security controls matters. Services like Lunyb provide link management with analytics and access controls that help reduce the risk of malicious redirects or unauthorised link tampering, which are common attack vectors in phishing-related breaches.
4. Train Your People
The overwhelming majority of Australian data breaches reported to the OAIC involve either malicious/criminal attacks (with phishing as the leading vector) or human error. Regular, role-specific training is the highest-leverage investment most organisations can make.
5. Test the Plan
Run tabletop exercises at least annually. Simulate scenarios such as ransomware, insider misuse, and vendor breaches so the response team knows what to do when the clock actually starts.
Common Types of Notifiable Breaches in Australia
According to OAIC's biannual Notifiable Data Breaches reports, the most frequently reported breach types include:
| Breach Source | Typical Examples | Proportion (Approx.) |
|---|---|---|
| Malicious or criminal attack | Phishing, ransomware, credential stuffing, hacking | ~65-70% |
| Human error | Emails sent to wrong recipient, misconfigured databases, lost devices | ~25-30% |
| System fault | Software bugs exposing data, misconfigurations | ~3-5% |
The health, finance, and government sectors consistently top the list for reported breaches — reflecting both the sensitivity of information they hold and the higher regulatory scrutiny they face.
How the NDB Scheme Compares with Global Frameworks
Australian organisations operating internationally often need to reconcile the NDB scheme with other frameworks. The following high-level comparison helps clarify key differences:
| Feature | Australia (NDB) | EU (GDPR) | UK (UK GDPR) |
|---|---|---|---|
| Notification trigger | Likely serious harm | Risk to rights and freedoms | Risk to rights and freedoms |
| Regulator notification timeline | As soon as practicable (with 30-day assessment) | 72 hours | 72 hours |
| Individual notification | Required if eligible breach | Required if high risk | Required if high risk |
| Maximum penalty | AU$50M / 30% turnover | €20M / 4% global turnover | £17.5M / 4% global turnover |
Notably, the reform agenda outlined in the Australian Government's response to the Privacy Act Review Report signals Australia may move closer to GDPR-style tight notification timelines in the coming years.
Recent Developments and What's Next
The Australian privacy landscape is in the middle of the largest reform cycle since the Privacy Act's introduction. Key developments to watch include:
- Tier-based civil penalty regime: A new mid-tier and low-tier structure allowing regulators to apply proportionate penalties for less serious contraventions.
- Statutory tort of serious invasion of privacy: Now enacted, giving individuals a direct cause of action.
- Removal of the small business exemption: Still under active consideration.
- Enhanced children's privacy protections and a Children's Online Privacy Code.
- Automated decision-making transparency requirements.
Organisations that treat compliance as an ongoing capability — rather than a one-time project — will be best positioned to adapt as these reforms roll out.
Reducing Breach Risk Through Everyday Security Hygiene
While enterprise-scale controls dominate compliance conversations, most breaches originate from mundane weaknesses: reused passwords, unpatched systems, phishing links clicked in a rush. Practical steps every organisation can take include:
- Deploying phishing-resistant multi-factor authentication (like FIDO2/passkeys)
- Using encrypted DNS resolvers on corporate networks
- Vetting third-party tools that handle customer data or URLs
- Enforcing HTTPS across all customer touchpoints
- Auditing external-facing links and redirects regularly
For teams that share a lot of links with customers or partners, choosing a trusted link management platform is part of the security stack. You can compare options in our 2026 buyer's guide to URL shorteners or read our honest review of Lunyb to see how link security features stack up.
Frequently Asked Questions
Do I have to notify the OAIC of every data breach?
No. You only need to notify the OAIC and affected individuals if the incident meets the definition of an "eligible data breach" — meaning it involves personal information, is likely to result in serious harm, and cannot be remediated in time to prevent that harm. Minor incidents that don't meet this threshold should still be logged internally.
How quickly must I notify affected individuals?
The Privacy Act requires notification "as soon as practicable" after you determine an eligible data breach has occurred. There is no fixed hour or day count, but delays without a clear justification can attract regulator scrutiny. If you're still assessing whether a breach is eligible, you have up to 30 days to complete that assessment.
What if the breach happened at a third-party supplier?
If both your organisation and the supplier hold the affected personal information, either can discharge the notification obligation on behalf of both — but only one notification is needed. It's essential to have contractual clarity about breach notification responsibilities in your supplier agreements before an incident occurs.
Does the NDB scheme cover employee records?
Currently, the employee records exemption in the Privacy Act means most private sector employers are not required to notify under the NDB scheme for breaches involving current or former employee records used for employment purposes. However, this exemption is one of the areas under active review, and best practice is to notify affected employees regardless.
What are the biggest mistakes organisations make when responding to a breach?
The most common mistakes include: delaying assessment while waiting for perfect information, underestimating the scope of affected individuals, providing vague notifications that don't help people take protective action, failing to document the decision-making process, and not preserving forensic evidence. A pre-prepared response plan avoids most of these pitfalls.
Final Thoughts
The Notifiable Data Breaches scheme is more than a reporting obligation — it's a forcing function for better privacy governance across Australian organisations. With penalties climbing, regulator activity increasing, and further reforms on the horizon, the question is no longer whether your organisation will face a data breach, but how prepared you'll be when it happens. Investing in strong data governance, robust security controls, well-trained staff, and a tested response plan is the most reliable way to keep an incident from becoming a catastrophe.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape shaped by PIPEDA, Quebec's Law 25, and the proposed CPPA. This guide covers the obligations, safeguards, breach response steps, and program-building strategies every Canadian organization needs in 2026.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and GDPR both protect personal data, but they differ significantly in consent, penalties, and individual rights. This guide compares Canada's privacy law with Europe's GDPR and explains what Canadian businesses need to do to stay compliant in 2026.
UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act reshapes how platforms handle your data, verify your age, and moderate content. Here's what it really means for your privacy in 2026 — and the practical steps you can take to stay in control.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR share the same goal but take very different paths to get there. This guide compares consent, breach notification, penalties, and cross-border rules — and shows how Singapore businesses can build one unified compliance program that satisfies both.